REFERENCE / GOVERNANCE / CONTROLSNIST CSF 2.0
- Publisher
- NIST
- Version / edition named
- 2.0
Source check: 2026-09-06 / recheck before use
Organize cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover.
Boundary: Use it as an outcome and communication layer; it is not itself a certification.
NIST CSF 2.0 resource center ↗REFERENCE / GOVERNANCE / CONTROLSNIST Risk Management Framework (SP 800-37 Rev. 2)
- Publisher
- NIST
- Version / edition named
- Rev. 2 / December 2018
Source check: 2026-09-06 / recheck before use
Frame prepare, categorize, select, implement, assess, authorize, and monitor activities for system and organizational risk.
Boundary: RMF language does not create an authorization to operate, authorizing-official decision, or agency approval.
NIST SP 800-37 Rev. 2 ↗REFERENCE / TESTINGNIST SP 800-115
- Publisher
- NIST
- Version / edition named
- Final / September 2008
Source check: 2026-09-06 / recheck before use
Structure technical security testing, planning, execution, analysis, and reporting.
Boundary: Apply it to an agreed testing scope and rules of engagement.
NIST SP 800-115 ↗REFERENCE / GOVERNANCE / CONTROLSNIST SP 800-30 Rev. 1
- Publisher
- NIST
- Version / edition named
- Rev. 1 / September 2012
Source check: 2026-09-06 / recheck before use
Support threat, vulnerability, likelihood, impact, and risk-assessment reasoning.
Boundary: Risk scores require organizational context and evidence quality.
NIST SP 800-30 Rev. 1 ↗REFERENCE / RESILIENCENIST SP 800-34 Rev. 1
- Publisher
- NIST
- Version / edition named
- Rev. 1 / updated November 2010
Source check: 2026-09-06 / recheck before use
Frame contingency planning, recovery priorities, alternate operations, and testing.
Boundary: A plan is not proof of recovery until it is exercised and evidenced.
NIST SP 800-34 Rev. 1 ↗REFERENCE / GOVERNANCE / CONTROLSNIST SP 800-53 Rev. 5
- Publisher
- NIST
- Version / edition named
- Rev. 5 / Release 5.2.0 published August 27, 2025
Source check: 2026-09-06 / recheck before use
Map security and privacy control families to systems, owners, and evidence.
Boundary: Control presence must be verified in the relevant system and scope.
NIST SP 800-53 Rev. 5 ↗REFERENCE / RESILIENCENIST SP 800-61 Rev. 3
- Publisher
- NIST
- Version / edition named
- Rev. 3
Source check: 2026-09-06 / recheck before use
Structure incident-response preparation, handling, coordination, and lessons learned.
Boundary: Incident readiness depends on people, authority, communications, and practice.
NIST SP 800-61 Rev. 3 ↗REFERENCE / SUPPLY CHAINNIST SP 800-161 Rev. 1
- Publisher
- NIST
- Version / edition named
- Rev. 1 / updates through 2024-11-01
Source check: 2026-09-06 / recheck before use
Assess cyber-supply-chain risk across products, services, dependencies, and suppliers.
Boundary: Vendor questionnaires alone are not sufficient evidence of supplier security.
NIST SP 800-161 Rev. 1 ↗REFERENCE / DEFENSE / CUINIST SP 800-171 Rev. 3 / 800-171A Rev. 3
- Publisher
- NIST
- Version / edition named
- Rev. 3 final / published May 14, 2024
Source check: 2026-09-06 / recheck before use
Discuss protection and assessment of controlled unclassified information in applicable nonfederal systems.
Boundary: Applicability, contract language, assessment method, and evidence expectations must be confirmed for each engagement.
NIST CUI publications (SP 800-171/171A Rev. 3) ↗REFERENCE / DEFENSE / CUINIST SP 800-172 Rev. 3 / 800-172A Rev. 3
- Publisher
- NIST
- Version / edition named
- Rev. 3 final / published May 13, 2026
Source check: 2026-09-06 / recheck before use
Frame enhanced CUI requirements and assessment procedures for critical programs and high-value assets when selected by the responsible federal agency.
Boundary: Enhanced CUI requirements are contract- and mission-dependent; this reference does not create a certification, clearance, or federal authorization.
NIST CUI publications (SP 800-172/172A Rev. 3) ↗REFERENCE / GOVERNANCE / CONTROLSCISA Cross-Sector Cybersecurity Performance Goals
- Publisher
- CISA
- Version / edition named
- Publisher-controlled current release; recheck latest
Source check: 2026-09-06 / recheck before use
Prioritize voluntary, high-impact cybersecurity practices for critical-infrastructure risk reduction and measurable improvement.
Boundary: CPGs are an orientation and prioritization aid, not a universal compliance result, sector designation, or regulator determination.
CISA Cybersecurity Performance Goals ↗REFERENCE / RESILIENCENCSC Cyber Assessment Framework 4.0
- Publisher
- UK NCSC
- Version / edition named
- 4.0 / page reviewed 2025-08-06
Source check: 2026-09-06 / recheck before use
Frame outcome-based cyber resilience assessment for essential functions, critical infrastructure, and public-sector contexts.
Boundary: CAF alignment is a scoped assessment conversation; it is not an NCSC endorsement, regulatory decision, or certification.
NCSC CAF collection ↗REFERENCE / GOVERNANCE / CONTROLSCIS Controls v8.1
- Publisher
- Center for Internet Security
- Version / edition named
- v8.1
Source check: 2026-09-06 / recheck before use
Translate common defensive priorities into a practical control improvement sequence.
Boundary: Control adoption should be tied to asset context, ownership, and evidence.
CIS Controls v8.1 ↗REFERENCE / TESTINGOWASP testing guidance
- Publisher
- OWASP
- Version / edition named
- Publisher-controlled WSTG release
Source check: 2026-09-06 / recheck before use
Support web, API, and application-security testing conversations and verification.
Boundary: Testing remains authorized, bounded, and appropriate to the application and environment.
OWASP Web Security Testing Guide ↗REFERENCE / GOVERNANCE / CONTROLSISO/IEC 27001:2022
- Publisher
- ISO
- Version / edition named
- 2022
Source check: 2026-09-06 / recheck before use
Support information-security management, control, risk, and evidence discussions.
Boundary: Readiness support does not create certification or an auditor’s opinion.
ISO/IEC 27001:2022 ↗REFERENCE / RESILIENCEISO 22301:2019 / ISO 31000:2018
- Publisher
- ISO
- Version / edition named
- 2019 + Amendment 1 (2024); to be revised / 2018
Source check: 2026-09-06 / recheck before use
Frame continuity, risk, impact, decision, and improvement conversations.
Boundary: Business continuity and risk management must reflect the organization’s actual objectives.
ISO 22301:2019 ↗REFERENCE / DEFENSE / CUIDoD CMMC Program
- Publisher
- U.S. Department of Defense
- Version / edition named
- DoD CIO current program page; recheck latest
Source check: 2026-09-06 / recheck before use
Frame defense-industrial-base questions about FCI/CUI scope, contract requirements, safeguarding evidence, assessment route, and responsible owner.
Boundary: CMMC applicability and required level depend on the solicitation or contract, information type, system boundary, flow-down, and current DoD rules; this page is not a CMMC assessment, certification, C3PAO, DIBCAC, or DoD authorization.
DoD CIO CMMC — About ↗REFERENCE / EU / REGULATORYEU NIS2 Directive (EU) 2022/2555
- Publisher
- European Union
- Version / edition named
- Directive (EU) 2022/2555 / EUR-Lex text
Source check: 2026-09-06 / recheck before use
Frame cybersecurity risk-management, incident-reporting, supply-chain, and governance questions for entities that fall within scope.
Boundary: Applicability depends on entity type, size, sector, national transposition, and competent authority; this reference is not a certification or legal determination.
EUR-Lex NIS2 Directive ↗REFERENCE / EU / REGULATORYEU DORA Regulation (EU) 2022/2554
- Publisher
- European Union
- Version / edition named
- Regulation (EU) 2022/2554 / in force
Source check: 2026-09-06 / recheck before use
Frame ICT risk management, incident reporting, resilience testing, and ICT third-party risk for applicable financial entities.
Boundary: Financial-sector scope, proportionality, supervisory expectations, and implementation requirements must be confirmed for the specific entity and service.
EUR-Lex DORA Regulation ↗REFERENCE / EU / REGULATORYEU GDPR Regulation (EU) 2016/679
- Publisher
- European Union
- Version / edition named
- Regulation (EU) 2016/679 / EUR-Lex text
Source check: 2026-09-06 / recheck before use
Frame personal-data security, breach, processor, accountability, and data-governance questions alongside privacy and legal review.
Boundary: GDPR is not a cybersecurity certification; roles, lawful basis, territorial scope, and obligations require the responsible privacy or legal owner.
EUR-Lex GDPR ↗REFERENCE / EU / REGULATORYEU Cyber Resilience Act (EU) 2024/2847
- Publisher
- European Union
- Version / edition named
- Regulation (EU) 2024/2847 / EUR-Lex text
Source check: 2026-09-06 / recheck before use
Frame secure-by-design, vulnerability-handling, product-security, and economic-operator questions for products with digital elements.
Boundary: Product scope, role, exemptions, obligations, and implementation timing require a specialist applicability review; this page is not a conformity assessment.
EUR-Lex Cyber Resilience Act ↗REFERENCE / EU / REGULATORYEU Critical Entities Resilience Directive (EU) 2022/2557
- Publisher
- European Union
- Version / edition named
- Directive (EU) 2022/2557 / EUR-Lex text
Source check: 2026-09-06 / recheck before use
Frame continuity, physical and cyber resilience, dependency, incident, and recovery questions for critical entities that fall within scope.
Boundary: Entity designation, sector, national implementation, risk measures, and competent-authority expectations must be confirmed; this is not a resilience designation or legal opinion.
EUR-Lex Critical Entities Resilience Directive ↗